Skip to main content

CWE archive

CWE-324 CVEs

Programmatic archive

20 CVEs tagged with CWE-3241 Critical, 4 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2026-52809

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-33012

Published Nov 7, 2025

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after accoun…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5342

Published Aug 14, 2025

The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.

CVSS 4.1 · Medium

CVE-2025-2291

Published Apr 16, 2025

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-31123

Published Mar 31, 2025

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7318

Published Sep 9, 2024

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deem…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6299

Published Jun 25, 2024

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as wel…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36031

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritte…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31895

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 28817…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31894

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 28817…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31893

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25679

Published Feb 9, 2024

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35401

Published Jan 10, 2023

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to fu…

CVSS 8.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2022-24732

Published Mar 9, 2022

Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3790

Published Jun 6, 2019

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1